Back Scworld GenAI could power dynamic, personalized phishing websites, Unit 42 warns
Per Tech Radar, security researchers are warning that generative AI (GenAI) could enable the creation of dynamic and personalized phishing websites, posing a new threat to cybersecurity.
Palo Alto Networks' Unit 42 has detailed a method where victims are directed to a seemingly harmless webpage. This page then prompts a legitimate large language model (LLM) API, which generates unique JavaScript code tailored for each user. This code is executed in the victim's browser, assembling a personalized phishing page without any static malicious code for traditional detection methods to intercept.
While the method is currently a proof-of-concept, the building blocks are already being utilized in various cybercrime activities, with LLMs increasingly used to generate obfuscated JavaScript and aid in malware campaigns.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
